{"id":18603,"date":"2026-09-22T08:04:24","date_gmt":"2026-09-22T08:04:24","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18603"},"modified":"2026-09-22T08:04:24","modified_gmt":"2026-09-22T08:04:24","slug":"iapp-cipt-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/iapp-cipt-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"IAPP CIPT Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cipt-exam-dumps\"><b>IAPP CIPT Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 361.<\/b><\/p>\n<p><b>A privacy engineer is reviewing a browser-based application that stores sensitive user data in localStorage even though the information is needed only during the current session. Which design is more appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Store the data permanently in localStorage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use session-scoped storage or avoid client-side persistence when feasible<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Copy the values into additional browser caches<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Expose the values through URL parameters<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Use session-scoped storage or avoid client-side persistence when feasible<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Client-side storage should match the duration and sensitivity of the information being processed. If data is needed only during one session, long-lived browser storage may create unnecessary persistence and increase exposure on shared or compromised devices. Privacy engineers should assess whether the data needs to be stored in the browser at all and, if so, choose a mechanism aligned with the required lifetime. Sensitive data should also be protected from unnecessary script access. Minimizing persistence supports storage limitation and reduces the amount of personal information that remains after the user finishes the activity.<\/span><\/p>\n<p><b>Question 362.<\/b><\/p>\n<p><b>A website uses several third-party scripts that can access page content and transmit network requests. Which privacy engineering activity is most important before deployment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review the scripts&#8217; data access, network behavior, permissions, and downstream destinations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assume all third-party scripts are privacy safe<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Give every script access to all page data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disable monitoring of third-party requests<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Review the scripts&#8217; data access, network behavior, permissions, and downstream destinations<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Third-party scripts can introduce privacy risks by collecting identifiers, page content, device information, or behavioral data that the host application did not intend to disclose. Privacy engineers should review what each script can access, inspect actual network traffic, verify configuration, understand downstream recipients, and determine whether collection aligns with the approved purpose. Dependency updates should also be monitored because behavior can change over time. Relying solely on documentation or contractual assumptions may miss runtime data flows. Third-party code should therefore be treated as part of the application&#8217;s privacy attack surface.<\/span><\/p>\n<p><b>Question 363.<\/b><\/p>\n<p><b>A mobile application includes a third-party SDK that begins transmitting a device identifier after a software update. Which control would most effectively help detect this change before release?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Longer data retention<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> More administrator accounts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Automated network inspection and privacy regression testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Broader production access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Automated network inspection and privacy regression testing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Third-party SDK behavior can change between versions, including the data collected or transmitted. Automated privacy regression tests can inspect network requests, compare expected endpoints and payloads, and flag newly introduced identifiers or transfers before deployment. Privacy engineers should combine this with dependency review and change management. Manual reviews alone may not scale when applications release frequently. Monitoring actual runtime behavior is particularly valuable because SDK documentation may not fully reflect what the code transmits under every configuration.<\/span><\/p>\n<p><b>Question 364.<\/b><\/p>\n<p><b>A website places a user&#8217;s email address in a URL query string during account recovery. Why should a privacy engineer recommend changing this design?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> URLs cannot contain text<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Query strings are always deleted immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> HTTPS makes URL exposure impossible<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The email may appear in browser history, logs, analytics systems, and referrer information**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The email may appear in browser history, logs, analytics systems, and referrer information<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Information embedded in URLs can propagate beyond the application itself. Query strings may be stored in browser history, web-server logs, proxy logs, monitoring platforms, analytics tools, screenshots, bookmarks, and referrer information. HTTPS protects the URL during transport from many network observers but does not prevent later storage or disclosure by application components. Privacy engineers should avoid putting unnecessary personal data or secrets in URLs and use safer mechanisms for passing state. Metadata leakage can create privacy exposure even when the underlying application is otherwise secure.<\/span><\/p>\n<p><b>Question 365.<\/b><\/p>\n<p><b>A company stores authentication tokens in ordinary application logs to simplify debugging. What should the privacy engineer recommend?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Exclude or securely redact authentication tokens from logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Retain the tokens indefinitely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Share the logs broadly with developers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Put additional credentials into the same log stream<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Exclude or securely redact authentication tokens from logs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Authentication tokens can grant access to accounts or services and should not appear in routine logs. If logs are compromised, broadly accessible, or retained for long periods, exposed tokens may create both security and privacy risks. Privacy engineers should design logging schemas that exclude secrets and minimize personal data while retaining enough diagnostic information for operations. Redaction, structured logging, access controls, and retention limits can help. Logs are often copied into centralized systems, so accidental inclusion of credentials can greatly expand their exposure.<\/span><\/p>\n<p><b>Question 366.<\/b><\/p>\n<p><b>A company wants to prevent sensitive personal data from leaving its network through unauthorized uploads or email attachments. Which class of control is most relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Content delivery networking<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Data loss prevention and egress controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Screen-resolution management<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Database indexing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Data loss prevention and egress controls<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data loss prevention controls can identify and restrict unauthorized movement of sensitive information through channels such as email, file uploads, removable media, or cloud applications. Egress controls can further limit which destinations systems are allowed to communicate with. Privacy engineers should use these controls as part of a broader strategy that includes classification, least privilege, encryption, monitoring, and user education. DLP is not perfect and can produce false positives, but it can help detect or prevent large accidental or malicious disclosures of personal information.<\/span><\/p>\n<p><b>Question 367.<\/b><\/p>\n<p><b>A company wants applications to enforce different handling rules based on whether data is public, internal, confidential, or highly sensitive. Which foundational capability best supports this?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Faster processors<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Additional backups<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Data classification and sensitivity labeling<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Universal access permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Data classification and sensitivity labeling<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data classification provides a structured way to identify sensitivity and apply appropriate controls. Labels can drive access restrictions, encryption requirements, retention rules, monitoring, export limitations, and handling procedures. Privacy engineers should ensure classifications reflect both the content and context of the data rather than relying solely on field names. Automated discovery can help, but human governance may still be needed for ambiguous cases. Classification is foundational because many downstream privacy and security controls depend on knowing which information requires stronger protection.<\/span><\/p>\n<p><b>Question 368.<\/b><\/p>\n<p><b>A company must preserve certain backup snapshots for operational recovery, but individual records may later be deleted from active systems. Which approach best addresses privacy in immutable backups?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Pretend backup copies do not exist<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Restore backups regularly so deleted records return to production<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Make backups publicly accessible<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Restrict backup access, define retention, prevent deleted records from re-entering active use, and expire backups according to policy**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Restrict backup access, define retention, prevent deleted records from re-entering active use, and expire backups according to policy<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Immutable backups can make immediate record-level deletion technically difficult. Privacy engineering should therefore focus on strong access controls, encryption, defined backup retention, and procedures that prevent deleted information from being restored into active processing without appropriate handling. When backups expire, they should be securely removed according to policy. The organization should document the lifecycle and ensure backups are used primarily for recovery rather than ordinary analytics. Backup architecture should support resilience without turning historical personal data into an uncontrolled permanent archive.<\/span><\/p>\n<p><b>Question 369.<\/b><\/p>\n<p><b>A company wants to understand which source system produced a customer attribute and how that value changed as it moved through analytics pipelines. Which capability is most relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data lineage and provenance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Screen caching<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Password rotation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Content delivery networks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Data lineage and provenance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data lineage describes how information moves through systems, while provenance helps explain where a value originated and how it was transformed. These capabilities are valuable for privacy because they support correction, deletion, accountability, impact analysis, and troubleshooting. If a questionable attribute appears in a downstream model or report, lineage can help identify the original source and intermediate transformations. Privacy engineers should incorporate lineage metadata into complex data platforms so lifecycle controls are not dependent on manual guesswork.<\/span><\/p>\n<p><b>Question 370.<\/b><\/p>\n<p><b>An organization creates a detailed identity graph that links email addresses, devices, purchase records, and location events across multiple services. What privacy risk should receive particular attention?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reduced screen performance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Increased linkability and comprehensive profiling<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Slower password hashing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Loss of database indexes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Increased linkability and comprehensive profiling<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity graphs can combine fragmented information into a highly detailed view of an individual. While this may support legitimate functions, it also increases the ability to profile behavior across contexts and may enable sensitive inference. Privacy engineers should assess whether all linkages are necessary, whether identifiers can be scoped by context, who can access the graph, and how long mappings are retained. Centralized identity resolution can become a powerful privacy risk if purpose boundaries are weak. The architecture should therefore limit unnecessary linkage rather than treating maximum correlation as inherently desirable.<\/span><\/p>\n<p><b>Question 371.<\/b><\/p>\n<p><b>An account-recovery process asks users to submit a passport scan even when a lower-risk verification method would be sufficient. Which privacy principle is most relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Data replication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Universal logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Indefinite retention<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Data minimization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Account recovery should verify the user while collecting the least additional personal information necessary. A passport contains far more information than many recovery scenarios require. If a lower-risk verification method can provide sufficient assurance, collecting a full identity document creates unnecessary exposure and lifecycle obligations. Privacy engineers should also consider retention, access restrictions, redaction, and whether temporary verification data can be deleted promptly. Security needs are important, but they should be balanced with minimization rather than automatically driving collection of the most sensitive evidence available.<\/span><\/p>\n<p><b>Question 372.<\/b><\/p>\n<p><b>A company stores biometric templates for authentication. Which design can reduce exposure compared with centrally storing reusable raw biometric images?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Publish the raw biometric images<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Store copies in multiple unrelated databases<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use the same unprotected template across all systems<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Prefer protected templates and on-device matching where appropriate**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Prefer protected templates and on-device matching where appropriate<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Biometric information is difficult or impossible to replace if compromised, so architecture should minimize centralized exposure. Protected templates and on-device matching can reduce the need to transmit or store raw biometric images centrally. Privacy engineers should also evaluate template revocability, unlinkability across systems, device security, fallback authentication, and retention. No biometric system is risk free, but designs that avoid unnecessary central repositories can reduce breach impact. Raw biometric data should not be retained merely because it is convenient.<\/span><\/p>\n<p><b>Question 373.<\/b><\/p>\n<p><b>A service wants to verify that a user meets an age threshold while collecting as little identity information as possible. Which design approach best supports this goal?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use an age-assurance method that returns only the required eligibility result where feasible<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Require a full identity profile from every user<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Retain government documents permanently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Share exact birth dates with all relying services<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Use an age-assurance method that returns only the required eligibility result where feasible<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privacy-preserving age assurance focuses on proving the required property without collecting or sharing more identity information than necessary. If the service needs only to know whether a threshold is met, a derived eligibility result can reduce disclosure compared with sharing an exact birth date or full identity document. Privacy engineers should still evaluate the reliability of the method, retention, security, and potential for linkage across services. Selective disclosure is generally preferable when the relying service does not need the underlying source attributes.<\/span><\/p>\n<p><b>Question 374.<\/b><\/p>\n<p><b>A user changes a privacy preference on one device, but the old setting remains active on other devices and backend services. Which capability should the system improve?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Screen rendering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Preference-state synchronization and propagation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Database compression<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Printer management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Preference-state synchronization and propagation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Privacy choices should be represented consistently across the systems that enforce them. If a preference changes on one device but remains stale elsewhere, the user may experience processing that contradicts their current choice. Privacy engineers should define a reliable source of truth, propagation mechanism, conflict-handling logic, and validation process for preference state. Distributed caches, mobile clients, event pipelines, and third-party systems may all need updates. Effective user control depends on synchronized technical enforcement, not merely on one local settings screen.<\/span><\/p>\n<p><b>Question 375.<\/b><\/p>\n<p><b>A user requests a copy of personal data in a form that can be reused in another service. Which engineering capability best supports portability?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Export data in a structured, commonly usable machine-readable format<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Provide screenshots only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Print the data and mail it<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Return only an internal database identifier<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Export data in a structured, commonly usable machine-readable format<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Portability is easier to support when systems can export relevant information in a structured format that other software can process. Privacy engineers should design data models and export services so records can be collected accurately from appropriate systems and represented consistently. The export process should also authenticate the requester and avoid including information belonging to other people unnecessarily. Screenshots or proprietary internal identifiers provide little practical reuse. A well-designed portability function treats the requirement as an engineering capability rather than an ad hoc manual task.<\/span><\/p>\n<p><b>Question 376.<\/b><\/p>\n<p><b>A company needs to verify the identity of someone making a data-access request. Which approach best balances security and privacy?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collect the maximum possible identification information every time<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Publish the requester&#8217;s account details<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Skip identity verification entirely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use verification proportionate to the risk while minimizing additional personal-data collection**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Use verification proportionate to the risk while minimizing additional personal-data collection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity verification is important because releasing personal data to the wrong person creates serious privacy risk. However, the verification process should not automatically require more sensitive information than necessary. Privacy engineers should use a method proportionate to the sensitivity of the requested data and available account context. Existing authenticated channels may sometimes provide sufficient assurance. Additional documents should be collected only when justified and retained no longer than necessary. The goal is to prevent unauthorized disclosure without creating a second, excessive identity-collection problem.<\/span><\/p>\n<p><b>Question 377.<\/b><\/p>\n<p><b>A multi-tenant SaaS product relies only on application code to separate tenants. Which additional database control can provide defense in depth against cross-tenant access?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Row-level security or equivalent tenant-aware database enforcement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Shared administrator credentials<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Public database access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Removing tenant identifiers from queries<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Row-level security or equivalent tenant-aware database enforcement<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application-level authorization is important, but database-level controls can add defense in depth. Row-level security can restrict which records a session or service is allowed to access based on tenant context. This reduces the risk that a coding error in one query exposes another tenant&#8217;s records. Privacy engineers should still test tenant isolation across APIs, caches, background jobs, exports, and administrative tools. Strong multi-tenant privacy requires consistent enforcement at multiple layers rather than relying on a single application check.<\/span><\/p>\n<p><b>Question 378.<\/b><\/p>\n<p><b>A company wants access decisions to consider a user&#8217;s role, department, data sensitivity, location, and the purpose of access. Which authorization model is especially suitable?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Anonymous access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Attribute-based access control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> One shared administrator account<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Public-read permissions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Attribute-based access control<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Attribute-based access control can make authorization decisions using multiple characteristics of the user, resource, environment, and requested action. This can support fine-grained privacy policies, such as allowing access only when a person&#8217;s role, department, purpose, and data sensitivity align with defined rules. Privacy engineers should keep policy logic understandable, testable, and auditable because overly complex rules can become difficult to manage. ABAC is particularly useful when simple role membership cannot express the context required for privacy-aware access decisions.<\/span><\/p>\n<p><b>Question 379.<\/b><\/p>\n<p><b>An attacker repeatedly tests an account-recovery endpoint to determine which email addresses are registered. What privacy issue does this represent?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User enumeration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Differential privacy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Homomorphic encryption<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Data compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. User enumeration<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">User enumeration occurs when system responses reveal whether a particular identifier corresponds to an existing account. Attackers may exploit different error messages, response times, or recovery behavior to build lists of registered users. This can expose membership in a service and support phishing or other attacks. Privacy engineers should use consistent responses, appropriate rate limits, monitoring, and careful recovery workflows. The goal is to provide legitimate account assistance without turning the endpoint into a directory of user identities.<\/span><\/p>\n<p><b>Question 380.<\/b><\/p>\n<p><b>A company wants privacy controls to remain effective as infrastructure, code, dependencies, and data flows change continuously. Which engineering approach is strongest?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Perform a privacy review once at initial launch<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Depend on policy documents without technical verification<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow configuration changes without monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Integrate privacy checks into CI\/CD, infrastructure changes, dependency review, runtime monitoring, and regression testing**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Integrate privacy checks into CI\/CD, infrastructure changes, dependency review, runtime monitoring, and regression testing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Modern systems change constantly, so privacy safeguards can degrade through code updates, new SDKs, configuration drift, infrastructure changes, or altered data flows. A mature privacy engineering program continuously validates important requirements. Automated tests can detect forbidden logging or excessive collection, dependency reviews can identify new data behavior, and runtime monitoring can reveal unexpected transfers. Infrastructure and configuration changes should also trigger appropriate review. Continuous privacy engineering reduces privacy debt and helps ensure protections remain effective throughout the operational lifecycle rather than only at initial launch.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full IAPP CIPT Exam Dumps and Practice Test Dumps &nbsp; Question 361. A privacy engineer is reviewing a browser-based application that stores sensitive user data in localStorage even though the information is needed only during the current session. Which design is more appropriate? Store the data permanently in localStorage 2. Use session-scoped storage or [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18603"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18603"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18603\/revisions"}],"predecessor-version":[{"id":18604,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18603\/revisions\/18604"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18603"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18603"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18603"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}